Your best option is to use downloadable access lists from a radius server (this is also the most manageable). Otherwise remove the sysopt connection permit-ipsec command and explicitly define the rules in the access=-lists
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.